| Summary: | flash security update to version 11.2.202.228 (CVE-2012-0772, CVE-2012-0773) | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Dave Hodgins <davidwhodgins> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | Normal | CC: | anssi.hannula, olivier.delaune, sysadmin-bugs, tmb |
| Version: | 1 | Keywords: | Security, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | http://get.adobe.com/flashplayer/ | ||
| Whiteboard: | |||
| Source RPM: | flash-player-plugin-10.3.181.34-0.1.mga1.nonfree.src.rpm | CVE: | |
| Status comment: | |||
|
Description
Dave Hodgins
2012-03-29 01:44:10 CEST
Remco Rijnders
2012-03-29 07:37:27 CEST
Keywords:
(none) =>
Security Flash Player 11.2.202.228 has been pushed to mga1 nonfree/updates_testing. Advisory: ============ Adobe Flash Player 11.1.102.63 contains a fix to a critical security vulnerability found in earlier versions. This vulnerability could cause a crash and potentially allow an attacker to take control of the affected system. This update resolves a memory corruption vulnerability in the NetStream class that could lead to code execution (CVE-2012-0773). References: http://www.adobe.com/support/security/bulletins/apsb12-07.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0773 ============ Note: CVE-2012-0772 is omitted above as it is a Windows-only issue. Updated Flash Player 11.2.202.228 packages are in mga1 nonfree/updates_testing as flash-player-plugin (i586 and x86_64) and flash-player-plugin-kde (i586 and x86_64). ========== Suggested testing procedure: ========== Package installs and Flash works. Status:
NEW =>
ASSIGNED Testing on i586 complete for the srpm flash-player-plugin-11.2.202.228-1.mga1.nonfree.src.rpm Testing using http://www.adobe.com/software/flash/about/ youtube, and menu/tools/more/Adobe flash player. Hello, Testing on 64-bits system. flash-player-plugin-11.2.202.228-1.mga1.nonfree.x86_64.rpm Testing using http://www.adobe.com/software/flash/about/ and youtube. CC:
(none) =>
olivier.delaune Validating the update Could someone from the sysadmin team push the srpm flash-player-plugin-11.2.202.228-1.mga1.nonfree.src.rpm from Nonfree Updates Testing to Nonfree Updates. Advisory: Adobe Flash Player 11.1.102.63 contains a fix to a critical security vulnerability found in earlier versions. This vulnerability could cause a crash and potentially allow an attacker to take control of the affected system. This update resolves a memory corruption vulnerability in the NetStream class that could lead to code execution (CVE-2012-0773). References: http://www.adobe.com/support/security/bulletins/apsb12-07.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0773 https://bugs.mageia.org/show_bug.cgi?id=5152 Keywords:
(none) =>
validated_update Update pushed Status:
ASSIGNED =>
RESOLVED |